Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
OpenIdentityPlatform
/
OpenAM
Public
Uh oh!
There was an error while loading.
Please reload this page
.
Notifications
You must be signed in to change notification settings
Fork
178
Star
894
Code
Issues
4
Pull requests
7
Discussions
Actions
Projects
Wiki
Security and quality
33
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Wiki
Security and quality
Insights
Actions: OpenIdentityPlatform/OpenAM
Actions
All workflows
Workflows
Build
Build
CodeQL
CodeQL
CodeQL
CodeQL
Copilot cloud agent
Copilot cloud agent
Copilot code review
Copilot code review
Dependabot Updates
Dependabot Updates
Package/Deploy
Package/Deploy
Release
Release
Show more workflows...
Management
Caches
CodeQL
CodeQL
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
codeql.yml
will be ignored since log searching is not yet available
141 workflow runs
141 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does no…
CodeQL
#141:
Commit
4b52a13
pushed by
vharseko
1h 21m 40s
master
master
1h 21m 40s
View workflow file
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources in openam-ui-api (4.3.1 -> 4.3.2)
CodeQL
#140:
Pull request
#1132
opened by
vharseko
1h 54m 30s
vharseko:fix/cve-2026-84375-js-yaml-api
vharseko:fix/cve-2026-84375-js-yaml-api
1h 54m 30s
View #1132
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#139:
Pull request
#1128
synchronize by
vharseko
1h 17m 31s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
1h 17m 31s
View #1128
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#138:
Pull request
#1131
synchronize by
vharseko
15m 9s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
15m 9s
View #1131
View workflow file
Do not log session ids, access tokens and password attributes (#1127)
CodeQL
#137:
Commit
b6c1d8b
pushed by
vharseko
17m 45s
master
master
17m 45s
View workflow file
GHSA-x8cj-3hqv-cgwh Session query REST endpoint lets a realm administ…
CodeQL
#136:
Commit
e0ba59d
pushed by
vharseko
1m 10s
master
master
1m 10s
View workflow file
Do not log session ids, access tokens and password attributes
CodeQL
#135:
Pull request
#1127
synchronize by
vharseko
36m 25s
vharseko:fix/sensitive-token-logging
vharseko:fix/sensitive-token-logging
36m 25s
View #1127
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#134:
Pull request
#1131
synchronize by
vharseko
29m 47s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
29m 47s
View #1131
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#133:
Pull request
#1128
synchronize by
vharseko
14m 57s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
14m 57s
View #1128
View workflow file
Do not log session ids, access tokens and password attributes
CodeQL
#132:
Pull request
#1127
synchronize by
vharseko
18m 25s
vharseko:fix/sensitive-token-logging
vharseko:fix/sensitive-token-logging
18m 25s
View #1127
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#131:
Pull request
#1131
synchronize by
vharseko
28m 25s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
28m 25s
View #1131
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#130:
Pull request
#1128
synchronize by
vharseko
15m 53s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
15m 53s
View #1128
View workflow file
Escape reflected request parameters in the sample servlets (#1129)
CodeQL
#129:
Commit
8891ce4
pushed by
vharseko
2h 2m 11s
master
master
2h 2m 11s
View workflow file
SetupUtils: pass chmod arguments to Runtime.exec as an array (#1126)
CodeQL
#128:
Commit
6006c77
pushed by
vharseko
23s
master
master
23s
View workflow file
[#1114] Fix precompile-jsps profile for the Jakarta EE 9 webapp (#1120)
CodeQL
#127:
Commit
f189e36
pushed by
vharseko
18s
master
master
18s
View workflow file
Escape reflected request parameters in the sample servlets
CodeQL
#126:
Pull request
#1129
synchronize by
vharseko
2h 38m 30s
vharseko:fix/sample-apps-xss
vharseko:fix/sample-apps-xss
2h 38m 30s
View #1129
View workflow file
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does no…
CodeQL
#125:
Commit
bfa7e10
pushed by
vharseko
2h 37m 3s
master
master
2h 37m 3s
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
CodeQL
#124:
Pull request
#1131
opened by
vharseko
14m 39s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
14m 39s
View #1131
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#123:
Pull request
#1128
synchronize by
vharseko
2h 7m 17s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
2h 7m 17s
View #1128
View workflow file
Escape reflected request parameters in the sample servlets
CodeQL
#122:
Pull request
#1129
opened by
vharseko
1h 34m 49s
vharseko:fix/sample-apps-xss
vharseko:fix/sample-apps-xss
1h 34m 49s
View #1129
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
CodeQL
#121:
Pull request
#1128
opened by
vharseko
28m 43s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
28m 43s
View #1128
View workflow file
Do not log session ids, access tokens and password attributes
CodeQL
#120:
Pull request
#1127
opened by
vharseko
1h 3m 32s
vharseko:fix/sensitive-token-logging
vharseko:fix/sensitive-token-logging
1h 3m 32s
View #1127
View workflow file
CodeQL
CodeQL
#119:
Scheduled
1h 45m 58s
master
master
1h 45m 58s
View workflow file
SetupUtils: pass chmod arguments to Runtime.exec as an array
CodeQL
#118:
Pull request
#1126
opened by
vharseko
55m 5s
vharseko:fix/setuputils-chmod-exec-args
vharseko:fix/setuputils-chmod-exec-args
55m 5s
View #1126
View workflow file
CVE-2026-84373 vitest: Path traversal / arbitrary file read via @vite…
CodeQL
#117:
Commit
5993d76
pushed by
vharseko
1h 20m 50s
master
master
1h 20m 50s
View workflow file
Previous
1
2
3
4
5
6
Next
You can’t perform that action at this time.